[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
> CVE-2026-66306 Skype for Business Information Disclosure Vulnerability
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
> Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intellig...
> CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
> CVE-2026-66304 Skype for Business Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
> Threat actors are giving AI agents a bigger role in cyberattacks
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagem...
> CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
> CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
> Mars Security brings threat intelligence to detection in real time
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and oth...
> CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
> “Zero-click” WeChat worm could hijack accounts and spread via a single call
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of ea...
> Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
> BigBear phishing crew nets thousands of Microsoft 365 credentials
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
> Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, preferring post-quantum connections wherever the origin supports it.
> The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantl...
> Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft
The scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons. The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek.
> Grindr Settles UK Data Privacy Claims for £26m
Grindr settled UK claims over alleged unlawful processing of sensitive user data
> Grindr settles HIV status data-sharing lawsuit for $35 million
Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
> Webinar: The forgotten Google Workspace access that can lead to a breach
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]
> French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack
French authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks against the country's tax authority and other organizations.